due diligence · insurtech · private equity · fintech

Due Diligence in Insurtech and Fintech Has Shifted From Verification to Thesis-Testing

3 August 2026 · Haden Kirkpatrick

The Short Answer

Due diligence in insurance, insurtech, and fintech is no longer a verification exercise, whereby you try to prove the details of the numbers in the slides. We are moving toward a period that demands “thesis-validating” efforts. Sophisticated PE and VC investors now want the real, hard evidence that the business in which they are putting their capital can scale…safely, competently, diligently, and in a compliant manner. That means four coordinated workstreams (commercial, technical, regulatory, and legal) are all layered over financial diligence on unit economics and operational runway.

If your diligence stops at the P&L level and goes no deeper than a data room walkthrough, you are investing in a storyline…not a business.

Why the Bar Moved

Buying or backing companies in a market where digital distribution, embedded finance, AI, cyber resilience is all good for growth. But regulatory readiness matters as much as product-market fit in these sectors. A slick front end and a growth curve are table stakes…it is the skin wrapping the muscles. The questions that actually determine what delivers successful returns sit underneath…they are the bones.

“Is the revenue durable?”

“Is the underwriting profitable?”

“Who owns the code?”

“Will the model survive contact with a regulator?”

I have sat at these tables, running strategy, innovation, and VC at large companies while advising founders and sponsors on the other side of the table. I see a consistent pattern…deals that disappoint their investors rarely fail because the market was too small.

They fail because the due diligence tested the wrong things…or (more to the point) tested them too shallowly.

Commercial Diligence: Customer Led, Not A Sideshow

Commercial diligence has become evidence based and customer led. Investors want market sizing, competitive position, customer quality, pricing power, churn, retention…and go-to-market effectiveness tested with primary research, including customer interviews, competitor sorts, and market scans. Management’s own framing is no longer enough…defensible market insights are (and have always been) the golden asset of any given strategy.

What good looks like

  • Revenue durability - Break the top line revenue streams into cohorts. Is growth from new logos, new segments, expansion, or price action? Retention and revenue by segment tells you whether you own a franchise or a leaky bucket. Are there customers who are keeping you afloat while others try to sink you? Are there customer segments that are more costly to buy than they deliver in profit? These are the key questions that every PE/VC investor needs to understand before they invest in a new firm.
  • Pricing power - Can the company raise prices (reasonably) without churn spiking? Your price is what you charge; the value is what you deliver. If you raise your price marginally and you have a churn spike, the value isn’t there in the minds of your customers. In insurance and fintech, pricing power often correlates with distribution control, switching costs, service expectations…but generally not brand. Brand is a fungible asset that can communicate these other aspects, but brands cannot create these assets by itself.
  • Customer quality - Are your customers diversified or concentrated? Are your underlying customers themselves healthy and secure, or brittle? A few large customers or a large customer base can flatter ARR, but might hide fragility. Unit economics are, and have always been, paramount. You “can’t lose money on every sale, but make it up in volume”. Having a customer base that is viable, healthy, durable, consistent…and ideally having multiple customer profiles of this type…are a massive moat on your financial statement.

Technical Diligence is Now Table Stakes

In tech-enabled financial services, technical diligence is no longer a “nice to have”. Standard review areas for these investments need to include software architecture reviews, scalability reviews, technical debt audits, security posture validations, vulnerability assessments, data governance audits, as well as vendor and licensing risk. And that is before you get to the integration requirements.

Founders are being asked to prove more than a growth narrative; investors and acquirers need to scrutinise accordingly. Diligence teams must evaluate who owns the code and IP; whether contractor assignments are clean; whether AI claims are supportable; whether the roadmap is realistic and funded; and whether there is deferred maintenance or hidden technical debt. Missing these elements turn them into poison pills. Not ones that might kill the deal…far worse. They end up being poised pills that kill the business and make the investment or acquisition untenable.

The AI / Data Governance Question

Where I see the most self-inflicted damage is in the data architecture. Lots of companies market AI capabilities that turn out to be rules engines, robotic process automation, or manual review sprints. In EU deals especially, sellers are tested hard on AI exposure, data handling, and regulatory obligations that may transfer to the acquirer on completion of the deal. This is particularly true where product claims depend on machine learning, alternative/synthetic data, or automation.

If your differentiation rests on top of a model, acquirers should execute special diligence on how it was trained, what data feeds it, whether you have the rights to that data, and whether the governance would survive a supervisor or regulator’s inspection.

Risk Transfer Diligence…the Ultimate Hedge

If the target is a carrier, MGA, broker, Insurtech, Fintech or other highly regulated entity, generic tech diligence is necessary, but insufficient. Insurance and financially specific analysis matters.
This is often the workstream that catches technology investors or acquirers off guard - you can buy a business with excellent software, but a broken risk platform. Test these limits directly and ensure that the company has the right kind of risk position given the business or sector they operate within.

Jurisdiction is Destiny

UK, US, and EU regulators make compliance diligence highly material in regulated fields like fintech or insurtech. Targets face jurisdiction focused scrutiny across licensing, data, privacy, and reinsurance.

Nexus issues arise in international firms where there are structures across borders that confuse or infect other operating units. Continental Europe is seeing PE activity consolidate in adjacent insurance/financial service categories, with heavily backed roll-up platforms driving consolidation and efficiencies through the standardization of platforms and shared services.

This is a powerful model, both operationally and financially. But it only raises the stakes on getting the regulatory picture right before you scale a platform across borders.

The practical reality is clear…a business that is compliant in one jurisdiction is not automatically compliant in the next. And if you engineer your systems and operating model for one jurisdiction, you might be missing the nuances of another. If your thesis depends on geographic expansion, due diligence on the regulatory path is as critical (or more) than the market opportunity and financial results.

Boards and investors do not want generic reports…they want a clear line from findings to the driving of business decisions. The common outputs are price adjustments, conditions to closing, indemnities, remediation plans, or a walk-away. In UK mid-market deals, technical diligence is often run on compressed timelines and framed explicitly as a go/no-go or price-setting exercise—which suits fast-moving sponsor processes.

For VC, the use case is slightly different but converging. Diligence increasingly de-risks follow-on and growth rounds: validating product scalability, security, team depth, and whether growth assumptions are realistic before a term sheet.

A practical diligence stack

  1. Commercial, including market, customers, pricing/ARPU, retention, go-to-market, and marginal costs.
  2. Technical, including architecture, scalability, security, IP ownership, tech debt, AI supportability, and innovation roadmapping/product development processes..
  3. Regulatory and legal, including licensing, data and privacy, cross-border nexus.
  4. Insurance and Risk mitigation, including loss runs, coverage, exclusions, day-one needs.
  5. Financial, including unit profitability, runway, layered across all four.

What this means for founders

If you are raising or selling, assume every claim will be tested by someone with domain expertise and a phone full of your customers. Clean up your IP assignments now. Be able to defend your AI claims. Know your loss ratios and your retention by cohort. The founders who clear diligence fastest are the ones who prepared for thesis-testing, not verification.

Key takeaways

  • Diligence has shifted from verifying numbers to testing whether the thesis survives scale, compliance, and durable economics.
  • Commercial diligence is now customer-led and evidence-based, not slide-led.
  • Technical and cyber diligence is table stakes; IP ownership and supportable AI claims are recurring failure points.
  • Insurance targets require dedicated risk-transfer diligence—loss runs and coverage, not just software.
  • Regulatory exposure is jurisdiction-specific and becomes more material as PE-backed platforms consolidate across borders.
  • Boards want findings tied to price, conditions, indemnities, or a walk-away—not a generic report.

Working on something this touches?

If you're a founder, board, or sponsor weighing a related move, I'm always glad to compare notes.

Start a conversation →

← All writing